Privacy Policy

Last updated: 14 June 2026

This Privacy Policy explains how AIGears ("we", "us", or "our") collects, uses, and shares information when you use the AIGears website, dashboard, REST API, and MCP server (together, the "Service"). It also describes the choices you have about your information. By using the Service you agree to the practices described here. This Policy should be read alongside our Terms of Service.

1. Who this Policy covers

The Service involves two broad groups of people:

  • Account users — developers and team members who register, log in, configure tools, and manage billing.
  • Approvers and recipients — people whose email addresses an account user provides so they can receive approval requests, deadline reminders, or other notifications. These people do not log in to manage configuration but do interact with signed links and emails we send on an account user's behalf.

2. Information we collect

Information you provide

  • Account and team data: your email address, password (stored only as a salted hash), team name, and profile details.
  • Billing data: subscription plan and billing records. Payments are processed by Stripe; we do not store full card numbers on our servers.
  • Tool configuration and content: the data you send when you use the Service — including webhook URLs, callback payloads, deadline summaries and metadata, approval action summaries and details, approver email addresses, watch source URLs and match rules, tags, and API key labels. Metadata and payloads are arbitrary content you define; please avoid including sensitive personal data you do not need us to process.

Information collected automatically

  • Audit and activity logs: an append-only record of tool calls, webhook deliveries and their outcomes, and approval decisions, including timestamps, request identifiers, and — for approval decisions — the approver's IP address and any comment they submit. Audit logs are retained according to your plan's retention window.
  • Usage and device data: log data such as IP address, browser type, and pages or endpoints accessed, used to operate, secure, and improve the Service.
  • Cookies: we use strictly necessary cookies for authentication and session management, and a preference cookie to remember your light/dark theme and language. If analytics is enabled, it is described in the "Analytics" section below.

Information collected from sources you watch

When you configure a watch, we fetch content from the URL, RSS feed, or JSON endpoint you specify, on the schedule you choose (subject to per-tier poll floors), and store snapshots or diffs to detect change. We identify our service in the request User-Agent and respect robots.txt and Cache-Control for URL sources. You are responsible for ensuring you have the right to monitor any source you configure.

3. How we use information

We use information to:

  • Provide and operate the Service — firing scheduled callbacks, tracking deadlines, delivering approval requests, and notifying you of watched changes.
  • Deliver webhooks and emails to the destinations and recipients you configure, and sign payloads so you can verify their origin.
  • Authenticate you, secure accounts, and prevent fraud and abuse.
  • Process payments and manage subscriptions through Stripe.
  • Maintain audit logs so you can inspect and trust what your agents have done.
  • Provide support, respond to enquiries, and send service-related communications.
  • Monitor, troubleshoot, analyse, and improve the Service.
  • Comply with legal obligations and enforce our Terms.

4. How we share information

We do not sell your personal information. We share it only as follows:

  • At your instruction: we deliver webhooks to the URLs you register and emails to the approvers and recipients you specify. The content of those deliveries is defined by you.
  • Service providers (sub-processors): we use trusted third parties to run the Service — for example, cloud hosting, Stripe for payments, and a transactional email provider for notifications. They may process information only on our instructions and under appropriate confidentiality and data-protection obligations.
  • Legal and safety: we may disclose information where required by law, to enforce our Terms, or to protect the rights, property, or safety of AIGears, our users, or others.
  • Business transfers: if we are involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.

5. Data retention

We retain account data for as long as your account is active. Audit and activity logs are retained for the window associated with your plan (for example, 7 days on the free tier, longer on paid tiers, as described on our pricing page). Tool state — such as completed callbacks, deadlines, approvals, and watch history — is retained as needed to provide the Service and to maintain the audit trail, then deleted or anonymised. When you close your account, we delete or anonymise your personal data within a reasonable period, except where we must retain it to comply with legal, accounting, or security obligations.

6. Security

We take reasonable technical and organisational measures to protect information, including encryption in transit, hashed passwords, signed and short-lived single-use URLs for human-facing surfaces such as approval pages, HMAC-signed webhook payloads, and access controls scoped to your Team. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Keep your account credentials and API keys confidential and rotate keys you believe may be compromised.

7. International transfers

We and our service providers may process and store information in countries other than your own. Where personal data is transferred across borders, we take steps to ensure it receives an appropriate level of protection consistent with applicable law.

8. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, or export your personal data, to object to or restrict certain processing, and to withdraw consent. You can update much of your account information directly in the dashboard. To exercise other rights, contact us at [email protected]. We will respond as required by applicable law. If you are an approver or recipient and wish to stop receiving messages, contact the account user who added you, or contact us and we will assist.

9. Analytics

If web analytics is enabled, we may use a third-party analytics provider to understand how the Service is used and to improve it. Analytics data is used in aggregate and is not used to sell your information. You can limit analytics cookies through your browser settings.

10. Children's privacy

The Service is intended for developers and businesses and is not directed to children. We do not knowingly collect personal information from anyone under the age of 16. If you believe a child has provided us personal information, contact us and we will delete it.

11. Changes to this Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you. Your continued use of the Service after changes take effect constitutes acceptance of the revised Policy.

12. Contact

If you have questions about this Privacy Policy or how we handle your information, contact us at [email protected].